Customer Due Diligence is the standard onboarding and monitoring process applied to normal-risk customers under AML rules.
Customer Due Diligence (CDD) is the baseline tier of customer scrutiny under FATF Recommendation 10. It covers four steps: identify the customer, verify the customer's identity using independent and reliable source documents, identify and verify the beneficial owner, and understand the purpose and intended nature of the business relationship.
Ongoing monitoring of the relationship is the fifth, continuous step.
CDD is the default. It is applied to every customer the regulated entity onboards, unless the customer qualifies for Simplified Due Diligence (SDD, low risk) or triggers Enhanced Due Diligence (EDD, high risk). The risk assessment underpinning that decision is itself a regulatory artefact: it must be documented, reviewed, and made available to the supervisor on request.
The CDD output is a customer file containing identity documents, ownership chart, expected transaction profile, source of funds statement, sanctions and PEP screening results, and the institution's own risk score for the customer. This file underpins ongoing monitoring throughout the relationship.
You will encounter CDD anytime a regulated entity onboards you. For corporate customers it includes documentation of the legal entity, identification of every UBO at the 25 percent threshold (or lower in some jurisdictions), and confirmation that none of the parties appear on sanctions or politically exposed person lists.
See what a company actually costs in year one, and how the jurisdictions compare on tax, capital and timeline.